Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vmware Spring Framework 权限许可和访问控制问题漏洞
Vulnerability Description
Vmware Spring Framework是美国威睿(Vmware)公司的一套开源的Java、JavaEE应用程序框架。该框架可帮助开发人员构建高质量的应用。 Spring Framework 3.2.4之前版本和4.0.0.M1版本中的Spring OXM包装器中存在权限许可和访问控制问题漏洞,该漏洞源于当使用JAXB封送处理器时,程序没有禁用实体解析。攻击者可通过外部实体声明与在(1)DOMSource,(2)StAXSource,(3)SAXSource,或(4)StreamSource中的实体
CVSS Information
N/A
Vulnerability Type
N/A